logo

Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

ID: 0209089d-0eb1-52f5-b5ec-7dde3d6f3ce2

STIX ID: report--0209089d-0eb1-52f5-b5ec-7dde3d6f3ce2

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-06-20

Date Updated: 2026-06-20

Author: [email protected] (The Hacker News)

...
...

**CVE-2026-4020** — A REST API permission flaw in the Gravity SMTP WordPress plugin can return the full system report (including API keys, tokens, and configuration) to unauthenticated callers; Wordfence has observed active exploitation (over 17 million blocked requests) and a patch is available in version 2.1.5 — site owners should update immediately and rotate exposed credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.